cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
341
Views
0
Helpful
4
Replies

FWSM and PIX 535 migration and differences

jeff.vargas
Level 1
Level 1

I'm migrating my PIX 535 config to a new FWSM and have come across some subtle differences. For instance, I have to apply a permit for ICMP to the interfaces and secondly all traffic does not seem to be allowed from inside to outside by default. Does anyone know of a document that outlines these differences?

Thanks,

4 Replies 4

thomas.chen
Level 6
Level 6

What is the version of software which you are using ?

Sorry for the late reply, I hope you read this. I'm on 2.3.4

ICMP to the interfaces is disabled by default.

Unlike PIX, FWSM does not allow default flow of traffic. You need to explicitly define rules for the traffic to flow.

Yes .. and also for getting ICMp to traverse the firewall module you need to enabled icmp inspection

fixup protocol icmp

fixup protocol icmp error

http://cisco.com/en/US/products/hw/switches/ps708/products_module_configuration_guide_book09186a00802c303c.html

more details can be found on the admin guide

I hope it helps .. please rate it it does !!!

Review Cisco Networking products for a $25 gift card